What is the best way to extract Azure DNS query logs for further analysis

2.7k views Asked by At

I'm not sure how to extract (and what is the preferred way) logs data of Azure DNS query logs for further analysis (as raw events).

Does it need to go through Azure monitor or maybe another way?

I would like to extract this data to event hub for further continuous processing. Is that possible?

Can i use/create diagnostic settings for DNS logs or export it like it is done for platform logs to different destinations (event hob/azure storage)?

2

There are 2 answers

2
John Hanley On BEST ANSWER

Azure does not support DNS query logs (at this time).

The only query-based metric is Query volume.

0
Norrin Rad On

If you use DNS proxy (through Azure firewall) I think it might provide you with additional logs.

Check DNS proxy in the following link:

https://learn.microsoft.com/en-us/azure/firewall/logs-and-metrics